Skip to content

[WRONG BRANCH] merge dev into main for the v2.33.0 release - #2552

Closed
lidge-jun wants to merge 87 commits into
mainfrom
dev
Closed

lidge-jun wants to merge 87 commits into
mainfrom
dev

Conversation

@lidge-jun

@lidge-jun lidge-jun commented Aug 25, 2026 •

Copy link
Copy Markdown
Owner

Promotion of dev into main for the 2.33.0 stable release.

Contents: the four OAuth login UX PRs (#2530, #2534, #2537, #2540), the mixed query/fragment authorization-response fix (#2543) found by an independent release-readiness audit, the release-gate isolation parity fix (#2546), and the api-usage overlay-version oracle fix (#2549).

The same code is already published as 2.33.0-preview.20260825 from preview, with the tarball verified by content.

Summary by CodeRabbit

  • New Features

    • Improved OAuth login with shared authorization hints, device codes, copyable URLs, and manual code/URL pasting across login screens.
    • Added an option to prevent automatic browser opening during login, with saved preferences and request-level control.
    • Added configurable per-model automatic compaction token limits.
    • Improved status reporting with routing details and unused-proxy warnings.
    • Added support for hosted xAI tool calls and better tool prioritization for Kiro.
    • Added Anthropic default reasoning-effort configuration.
  • Bug Fixes

    • Improved OAuth fragment handling, retry behavior for empty completions, startup refresh consistency, and Codex shim diagnostics.
  • Documentation

    • Updated configuration, provider login, lifecycle, and retry guidance.

lidge-jun and others added 30 commits August 14, 2026 21:30
preview now carries the same tree as main and dev (36aed0b). The version
string is the only difference, which is what the release workflow requires:
preview publishes prerelease versions under the 'preview' dist-tag.

Before this, the preview channel was 12,065 lines behind dev and still shipped
the Compatibility Lab on every install's request path.
chore(preview): promote dev for the v2.20.0 line
[WRONG BRANCH] Merge dev into preview: Windows suite green
Merge dev into preview: ignore leftover test temp files
Merge main into preview: v2.24.2 release
Promote dev to preview: Wave 5 campaign (107 commits)
Promote dev to preview: CodeQL #87 ReDoS fix + closeout correction
Promote dev to preview: Wave 5 record corrections
Promote dev to preview: alert-precision record
Promote dev to preview: post-scan closing note
Promote dev to preview: final Wave 5 errata
Promote dev to preview: Wave 5 closing record
Promote dev to preview: v2.25.0 release train
promote: dev to preview for v2.26.0-preview.20260819
fix(gui): show the device code and authorization link on every login surface
fix(gui): render the login hint during a first-time provider add
feat(oauth): let the operator decline a proxy-side browser open
fix(oauth): read code and state from a redirect URL fragment
fix(oauth): never pair a code and state from different URL components
merge dev into preview for the v2.33.0-preview.20260825 release
…parity

fix(release): run the preflight suite in the same groups CI does
merge dev into preview for the v2.33.0-preview.20260825 release (release-gate parity)
…on-oracle

test(usage): stop asserting the overlay version against a moving oracle
@lidge-jun
lidge-jun requested a review from Ingwannu as a code owner August 25, 2026 11:02
@coderabbitai

coderabbitai Bot commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

Review Change Stack

Caution

Review failed

The pull request is closed.

ℹ️ Recent review info
⚙️ Run configuration

Configuration used: Path: .coderabbit.yaml

Review profile: ASSERTIVE

Plan: Pro Plus

Run ID: 1df3e9cf-0c8a-45ee-969a-2bd5ce625bba

📥 Commits

Reviewing files that changed from the base of the PR and between 71c57ea and e1fb675.

📒 Files selected for processing (131)
  • devlog/_plan/260825_oauth_login_ux/000_baseline_and_scope.md
  • devlog/_plan/260825_oauth_login_ux/001_current_state_inventory.md
  • devlog/_plan/260825_oauth_login_ux/002_plan_audit.md
  • devlog/_plan/260825_oauth_login_ux/003_delivery_map.md
  • devlog/_plan/260825_oauth_login_ux/010_wp2_shared_login_hint.md
  • devlog/_plan/260825_oauth_login_ux/020_wp3_first_add_parity.md
  • devlog/_plan/260825_oauth_login_ux/030_wp4_browser_open_control.md
  • devlog/_plan/260825_oauth_login_ux/040_wp5_paste_normalization.md
  • devlog/_plan/260825_oauth_login_ux/090_merge_train_closeout.md
  • devlog/_plan/260825_operator_visibility_train/000_baseline_and_scope.md
  • devlog/_plan/260825_operator_visibility_train/001_current_state_inventory.md
  • devlog/_plan/260825_operator_visibility_train/002_plan_audit.md
  • devlog/_plan/260825_operator_visibility_train/010_wp2_issue2457_sidecar_backend_resolution.md
  • devlog/_plan/260825_operator_visibility_train/020_wp3_issue2411_status_routing_visibility.md
  • devlog/_plan/260825_operator_visibility_train/030_wp4_issue2412_version_manager_shim.md
  • docs-site/src/content/docs/fr/reference/configuration/providers.md
  • docs-site/src/content/docs/guides/providers.md
  • docs-site/src/content/docs/ja/reference/configuration/providers.md
  • docs-site/src/content/docs/ja/reference/configuration/server.md
  • docs-site/src/content/docs/ko/reference/configuration/providers.md
  • docs-site/src/content/docs/ko/reference/configuration/server.md
  • docs-site/src/content/docs/reference/cli/lifecycle.md
  • docs-site/src/content/docs/reference/configuration/providers.md
  • docs-site/src/content/docs/reference/configuration/server.md
  • docs-site/src/content/docs/ru/reference/configuration/providers.md
  • docs-site/src/content/docs/ru/reference/configuration/server.md
  • docs-site/src/content/docs/tr/reference/configuration/providers.md
  • docs-site/src/content/docs/zh-cn/reference/configuration/providers.md
  • docs-site/src/content/docs/zh-cn/reference/configuration/server.md
  • docs-site/src/content/docs/zh-tw/reference/configuration/providers.md
  • gui/src/components/AddProviderModal.tsx
  • gui/src/components/QuotaBars.tsx
  • gui/src/components/add-codex-account-waiting-step.tsx
  • gui/src/components/add-provider-modal-reducer.ts
  • gui/src/components/add-provider-oauth-pane.tsx
  • gui/src/components/login-url-block.tsx
  • gui/src/components/open-browser-pref-toggle.tsx
  • gui/src/components/provider-catalog/ProviderCatalog.tsx
  • gui/src/components/provider-catalog/login-hint-visibility.ts
  • gui/src/components/provider-workspace/AnthropicAccountPoolSettings.tsx
  • gui/src/components/provider-workspace/ProviderAuthPanel.tsx
  • gui/src/components/use-add-codex-account-oauth.ts
  • gui/src/components/use-add-provider-oauth.ts
  • gui/src/i18n/de.ts
  • gui/src/i18n/en.ts
  • gui/src/i18n/fr.ts
  • gui/src/i18n/ja.ts
  • gui/src/i18n/ko.ts
  • gui/src/i18n/ru.ts
  • gui/src/i18n/tr.ts
  • gui/src/i18n/zh-TW.ts
  • gui/src/i18n/zh.ts
  • gui/src/oauth-open-browser-pref.ts
  • gui/src/pages/Providers.tsx
  • gui/src/pages/Startup.tsx
  • gui/src/pages/dashboard-shared.ts
  • gui/src/pages/providers-page-modals.tsx
  • gui/src/pages/use-providers-oauth.ts
  • gui/src/styles.css
  • gui/src/styles/login-url-block.css
  • gui/src/styles/provider-catalog.css
  • gui/tests/anthropic-pool-card-layout.test.ts
  • gui/tests/startup-revisit-cache.test.tsx
  • package.json
  • scripts/release.ts
  • src/adapters/anthropic.ts
  • src/adapters/kiro-tools.ts
  • src/bridge.ts
  • src/claude/context-windows.ts
  • src/cli/doctor.ts
  • src/cli/index.ts
  • src/cli/status.ts
  • src/codex/auth-api.ts
  • src/codex/autostart-health.ts
  • src/codex/catalog/aggregation.ts
  • src/codex/catalog/effort.ts
  • src/codex/catalog/metadata.ts
  • src/codex/catalog/parsing.ts
  • src/codex/catalog/provider-fetch.ts
  • src/codex/catalog/sync.ts
  • src/codex/convergence.ts
  • src/codex/shim.ts
  • src/config.ts
  • src/oauth/callback-server.ts
  • src/oauth/kimi.ts
  • src/oauth/open-browser-choice.ts
  • src/providers/auto-compact-budget.ts
  • src/providers/xai-transport.ts
  • src/server/auth-cors.ts
  • src/server/management/agent-settings-routes.ts
  • src/server/management/config-routes.ts
  • src/server/management/model-rows.ts
  • src/server/management/oauth-account-routes.ts
  • src/server/management/provider-routes.ts
  • src/server/responses-undeclared-tool-guard.ts
  • src/server/responses/core.ts
  • src/server/responses/empty-completion-guard.ts
  • src/types.ts
  • src/types/config.ts
  • src/types/provider.ts
  • src/types/tools.ts
  • structure/04_transports-and-sidecars.md
  • tests/anthropic-reasoning.test.ts
  • tests/api-usage.test.ts
  • tests/auto-compact-budget.test.ts
  • tests/autostart-health.test.ts
  • tests/bridge-legacy-shell-normalization.test.ts
  • tests/claude-context-windows.test.ts
  • tests/cli-help.test.ts
  • tests/codex-auth-modal-status.test.ts
  • tests/codex-catalog.test.ts
  • tests/codex-convergence-account-selectors.test.ts
  • tests/codex-shim.test.ts
  • tests/config.test.ts
  • tests/empty-completion-guard.test.ts
  • tests/kiro-adapter.test.ts
  • tests/management-provider-validation.test.ts
  • tests/native-model-toggle.test.ts
  • tests/oauth-device-code-contract.test.ts
  • tests/oauth-first-add-hint.test.ts
  • tests/oauth-login-open-browser.test.ts
  • tests/oauth-manual-code.test.ts
  • tests/oauth-open-browser-choice.test.ts
  • tests/provider-workspace-auth.test.ts
  • tests/quota-bars-rows.test.ts
  • tests/release-helper.test.ts
  • tests/responses-undeclared-tool-guard.test.ts
  • tests/settings-oauth-open-browser.test.ts
  • tests/sidecar-settings-web-search-gate.test.ts
  • tests/update-stop-first.test.ts
  • tests/xai-transport.test.ts

📝 Walkthrough

Walkthrough

This change combines OAuth login UX improvements, configurable model compaction limits, operator diagnostics, tool handling updates, retry behavior, documentation, and test infrastructure changes.

Changes

OAuth login experience

Layer / File(s) Summary
Shared login hints and browser choice
gui/src/components/*, src/oauth/*, src/server/management/oauth-account-routes.ts
OAuth flows now display URLs, device codes, instructions, and paste controls through shared GUI components. Browser auto-open behavior supports persisted and per-request choices.
Callback parsing and first-add flow
src/oauth/callback-server.ts, gui/src/pages/*, gui/src/components/provider-catalog/*
Callback fragments are parsed with state validation. First-add provider rows can display the active login hint and accept pasted callback data.
OAuth documentation and tests
docs-site/src/content/docs/guides/providers.md, tests/oauth-*.test.ts
Remote-browser, device-code, browser-choice, fragment parsing, and first-add behavior are documented and tested.

Model catalog compaction budgets

Layer / File(s) Summary
Configuration and management contracts
src/types/*, src/config.ts, src/providers/auto-compact-budget.ts, src/server/management/*
Providers accept validated per-model soft compaction limits. PATCH operations merge, delete, or clear entries.
Catalog propagation and clamping
src/codex/catalog/*, src/codex/convergence.ts, src/server/management/model-rows.ts
Limits propagate through native, combo, custom, fallback, and trusted registry rows. Values remain bounded by context and input ceilings.
Catalog validation tests and translated references
tests/auto-compact-budget.test.ts, tests/codex-catalog.test.ts, docs-site/src/content/docs/*/reference/configuration/providers.md
Tests cover validation, persistence, inheritance, clamping, and unknown-context behavior. Provider references describe the new field.

Operator visibility and runtime behavior

Layer / File(s) Summary
Sidecar and status diagnostics
src/server/management/config-routes.ts, src/server/management/agent-settings-routes.ts, src/cli/*, src/codex/autostart-health.ts
Submitted web-search backends are validated against the full supported union. Status output includes routing details and live-proxy warnings.
Shim lifecycle diagnostics
src/codex/shim.ts, docs-site/src/content/docs/reference/cli/lifecycle.md, tests/codex-shim.test.ts
Version-manager-owned Codex paths are classified and excluded from replacement adoption. Ineligible results include diagnostics.
Adapters, tools, and retry behavior
src/adapters/*, src/bridge.ts, src/server/responses/*, src/types/tools.ts
Anthropic defaults, Kiro prioritization, legacy tool normalization, xAI hosted calls, and pre-output EOF retries are updated with regression coverage.

Estimated code review effort: 5 (Critical) | ~120 minutes

Sequence Diagram(s)

sequenceDiagram
  participant GUI
  participant OAuthRoute
  participant OAuthProvider
  participant CallbackParser
  GUI->>OAuthRoute: start login with openBrowser preference
  OAuthRoute->>OAuthProvider: create login flow
  OAuthProvider-->>OAuthRoute: URL, device code, instructions
  OAuthRoute-->>GUI: login metadata
  GUI->>CallbackParser: submit pasted URL or code
  CallbackParser-->>OAuthRoute: validated code and state
  OAuthRoute-->>GUI: login result
Loading
✨ Finishing Touches 💡 2
⚔️ Resolve merge conflicts 💡
  • Resolve merge conflict in branch dev
🛠️ Fix failing CI checks 💡
  • Create stacked PR
  • Commit on current branch
📝 Generate docstrings
  • Create stacked PR
  • Commit on current branch
🧪 Generate unit tests (beta)
  • Create PR with unit tests
  • Commit unit tests in branch dev

Thanks for using CodeRabbit! It's free for OSS, and your support helps us grow. If you like it, consider giving us a shout-out.

❤️ Share

Comment @coderabbitai help to get the list of available commands.

@github-actions

Copy link
Copy Markdown
Contributor

✅ Deterministic PR hygiene checks passed.

@github-actions github-actions Bot changed the title merge dev into main for the v2.33.0 release [WRONG BRANCH] merge dev into main for the v2.33.0 release Aug 25, 2026
@github-actions

github-actions Bot commented Aug 25, 2026 •

Copy link
Copy Markdown
Contributor

⏳ DRAFT

  • wrong target branch (main); retarget to dev. UI screenshot required.

What to do

  • Retarget this PR to dev — all contributions go to dev.
  • Add a screenshot of the UI change to the PR description.

Its title has been prefixed with [WRONG BRANCH].
This pull request was already a draft. Its draft status will be preserved after every issue above is resolved.

@github-actions
github-actions Bot marked this pull request as draft August 25, 2026 11:03
@lidge-jun lidge-jun closed this Aug 25, 2026

@chatgpt-codex-connector chatgpt-codex-connector Bot left a comment

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

💡 Codex Review

Here are some automated review suggestions for this pull request.

Reviewed commit: e1fb675595

ℹ️ About Codex in GitHub

Your team has set up Codex to review pull requests in this repo. Reviews are triggered when you

  • Open a pull request for review
  • Mark a draft as ready
  • Comment "@codex review".

If Codex has suggestions, it will comment; otherwise it will react with 👍.

Codex can also answer questions or update the PR. Try commenting "@codex address that feedback".

Comment thread src/codex/shim.ts
|| normalized.includes("/mise/shims/")
|| normalized.includes("/.asdf/installs/")
|| normalized.includes("/.asdf/shims/")
|| normalized.includes("/.volta/");

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P1 Badge Recognize Volta's default Windows installation path

On Windows, Volta normally installs under %LOCALAPPDATA%\Volta\bin, which normalizes to a path containing /volta/, not /.volta/. Consequently this classifier returns false for the standard Windows Volta layout, so after a Volta upgrade autoRestoreCodexShim can adopt and wrap the replacement binary again; the next upgrade destroys that shim and can silently leave Codex routing native. Match the Windows Volta layout as well and cover it with the actual default path rather than C:\Users\u\.volta\....

Useful? React with 👍 / 👎.

Comment on lines +29 to +32
export function OpenBrowserPrefToggle({ serverDefault = true }: { serverDefault?: boolean }) {
const t = useT();
const [choice, setChoice] = useState<boolean | undefined>(readOpenBrowserPref);
const open = choice ?? serverDefault;

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Render the persisted browser-open setting in the toggle

When oauthOpenBrowser is persisted as false and this browser has no localStorage preference, both current call sites omit serverDefault, so this default makes the “Don't open a browser” checkbox appear unchecked even though login requests omit openBrowser and the server therefore does not open one. The control visibly contradicts the effective configuration; pass the fetched setting into the component or represent the inherited server state explicitly.

AGENTS.md reference: gui/AGENTS.md:L10-L10

Useful? React with 👍 / 👎.

Comment thread src/cli/index.ts
Comment on lines +851 to +853
for (const line of unusedProxyWarningLines({
proxyUp: Boolean(status.json.proxy.pid || status.json.proxy.health.ok),
routingKind: status.json.startup.routingKind,

Copy link
Copy Markdown

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

P2 Badge Exclude stale PID files from the unused-proxy warning

When a stale PID file exists but the health check fails, collectStatus deliberately reports proxy.running: false and labels the PID as stale, yet this new predicate treats the mere non-null PID as an active proxy and prints “the running proxy is unused.” That makes the new routing diagnostic contradict the status immediately above it; derive proxyUp from proxy.running or a successful health check instead of PID-file presence.

Useful? React with 👍 / 👎.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

8 participants